Hacker Newsnew | past | comments | ask | show | jobs | submit | tdrz's commentslogin

This can happen with modern fintech because of greed. There's a reason they can offer such cheap services. The customer takes a risk in return. Now that risk has materialized.

Yes, because it's _only_ "modern fintech" that are susceptible to social engineering, right?

Oh.. https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-ho...


I see your point about greed. Thanks. Let me still contrast that: GPT6 has 99.9 in ARC-AGI 3 and multiple bug-bounty programs closed due to the sheer amount of automated attacks and reports.

And they are "FinTech". "Oh, that email looks legit, let's just hand out the data.", like they have never witnessed phishing from the old days... am curious about the story here. That PR-spokesperson is more than damaging...


Here is one of the replies I got during my conversation with their agent (unsure if human or automated):

"Your personal data must be held until it is permissible to erase it in accordance with the law. Rest assured, it is totally secure and only held for this purpose."

This was in the same conversation where I sent them the article.


Was it the same agent that released the data?

My dialogue:

> Hi, me affected by your breach?

Them:

> "I have checked our records and can confirm that you have not received any notifications or communications regarding any security incidents or data breaches in the past 30 days.

> We take your privacy extremely seriously. All data transmissions between our mobile apps, servers, and third parties are fully encrypted, and your personal information is stored in secure data centres with restricted access. If there is ever any security incident that impacts your account, we will always contact you directly with instructions.

> Are you asking because you recently received a suspicious email, text message, or noticed an unusual transaction on your account? Let me know, and we can investigate that together."

... bot stuffs.


Revolut are well known for using automated systems for all support and it being difficult/impossible to talk to an actual human

I asked if my data was compromised, they said no, but how can I trust/verify this?

You can't, really. Banking legislation does not require them to tell you.

Banking legislation in the UK does require them to tell you for this kind of breach.

Breach yes, but if they cannot 100% sure identify if your data was given out falsily, then they cannot say. They're not allowed to disclose that they provide your information to LE. So they can only inform you directly if they're 100% sure the specific information request response was sent to false entity. This is very hard to do.

Data laws in EU mandate that a company has to tell you every single entity it has shared your data with, regardless of the sector they operate in.

What you're referring to is that a bank does not require to tell you whether your account is going through specific checks (anti laundering and such).


This was a targeted attack towards specific individuals, probably carried out by a state actor or someone after data of very valuable individuals. Unless you're one of those (oligarch, etc), you're probably fine.

Other banks do not require selfies, so there are other options

But they are verifying customers in person with account creation, this is an online bank

> But they are verifying customers in person with account creation, this is an online bank

Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.


Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?

FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad.

Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.


>The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.

People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.

>leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

don't some of them require a selfie while holding legible official documentation?


No, it’s most certainly patently ridiculous.

> Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.

Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that?

> don't some of them require a selfie while holding legible official documentation?

You can of course do KYC as stupidly as you like (zoom calls anyone?) - Revolut (and their providers) obviously separate document presentation from the liveness check (and fyi this is a short video, not a selfie. The selfie they are talking about is just a capture from the video)


>No, it’s most certainly patently ridiculous

Is your argument supposed to be more convincing because you added the word "patently"?

>What does that mean though?

It means that when you find a way to bypass purely online identity verification checks executing fraud at scale is easier than the physical alternative. As you would say, this is patently obvious.


For security reasons, obviously! That way they wouldn't leak selfies because they wouldn't have any.

Sending your new/potential customers to your competitor doesn't sound very sensible.

Seems like a thing you should be able to do at the post office.

What does post office have to do with identity verification?

In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They're already depended on for identity verification quite a lot.

You can receive mail to any name at your address.

Some post offices in the US also function as a so called notary public. Basically, they can verify your identity and attest that it's you who sent/did something.

This is used quite often for important things that don't have offices themselves.


This is a 100% online bank account you typically open from an app. The typical clientele will just use the "selfie" auth.

The issue is that there is no alternative to the "selfie" auth in case of Revolut.

Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.

I have accounts with 2 other banks. They never asked for a selfie.

Same, they never asked for a selfie back then.

Try opening one now. Today it's hard to get a hire purchase contract as an existing custoner (already known and verified) without photos of the ID and selfie.


Likewise, opened a couple in the past few years and never saw this. That said, bank lobbies have tons of ambient cameras anyway, so they don't really need a selfie.

At least one traditional UK bank requires a selfie and a passport scan.

Can I use it to embed PGlite in an app and distribute it like that? ie not to dependend on the host JIT/interpreter

If Wasmi supports all the Wasm proposals that you need for PGlite and if Wasmi supports all the WASI features you need (Wasmi only supported the standard WASI features without extensions), then Wasmi should work for your use-case. :)

Wasmi itself can be compiled to WebAssembly.


This! I live in Western Europe and have never owned a car. I mostly travel by public transport or bike. I rent a car about once a year, but could do without that as well. Before people tell me that I am an exception: I know other people like me in various other places in Europe! It is possible and actually good for your body to have to move, at least to the train station, carrying groceries etc.


>This! I live in Western Europe and have never owned a car.

I'm also in Western Europe and almost always needed a car for my commutes to work, unless I was willing to accept a 1-2+ h public transport commute each way, because tech employers where I live love locating their offices in the sticks where land is cheap because they're broke and cheap, and the city hasn't significantly updated public transport infrastructure in ~30 years, but the population and size of the metro area grew by like 3x.

>Before people tell me that I am an exception: I know other people like me in various other places in Europe!

The thing is, Western Europe is not a country, but a collection of various countries with various economies, cities, and infrastructure, and various people with various housing and career locations, some close and well connected to public transport, some not at all, and from my circle of acquaintances, yes, you are the exception, as most people I know get to work by car.

So, you can't possibly throw such blanket statement over everyone in Western Europe, unless you're massively obtuse or living in a bubble without realizing it.

Like, I'm sure most people in Munich, Paris, London, Madrid, Vienna, etc can easily get to work on the excellent public transport they have, but I don't live there and don't have such amazing public transport, so then car it is for us.

>It is possible and actually good for your body to have to move, at least to the train station, carrying groceries etc.

Bruh, I only need a car just to get to work in reasonable time, not to move or carry groceries.

I get my groceries from the supermarkets 5-10 minute walking distance to my place, but I don't have the luxury of employment jobs within the same distance, so car it is, unless I want to be wasting my life switching connections between slow and infrequent trams, busses and trains which often suffer delays.

And regarding the "body movement" as a pro for public transport, I'd rather have more free time to move in gym and to the workouts my body condition needs, rather than waste my time walking and sitting/standing on public transport, as that's not an actual workout but a waste of time, as all you can do is browse HN on the phone with the hand that's not grabbing the bar. Driving is also a waste of time, but at least it saves me almost 1 hour each way which is massive time save that I can use how I like.


I'm an OSS maintainer and to me it's not just about the review itself. Being greeted by a wall of text for every little small thing is counter-productive. I hate going through 2 pages of text for each PR. It usually shouldn't take more than a couple of sentences if you understand the issue and the solution.

But most important for me: lots of time the PR just adds even more code, although other options do exist (ie sometimes REMOVING some code). You have to know the codebase well in order to find those objectively better solutions.


I've seen it. Walls of text with stereotypically worded non-summaries that just repeat all of the code in words, mutating values all over the place instead of the obvious canonical one place that touches related values...

Yeah you can use LLMs, but don't let me notice it from the quality of the output.

I've noticed that LLMs seem to be especially bad at things relating to space, position and movement. I guess they have to synthesize that part of human intelligence entirely, it's not in the words.


How do you handle them? I'm not facing this problem as the team I work with is very senior and have good taste and discipline. But I can imagine it will be a problem at some point, and I frequently have to personally tell Claude to rewrite it's vomit in English. That's probably step one for people submitting poorly written PRs, reject them until they are written clearly and concisely. And if they are too big, also rejecting them and telling them to go back to the drawing board and submit smaller more focused change. But I'm not int his position so I'm taking an educated guess.


Give https://pyor.review a shot if you’re struggling with PR reviews on github.


Or, the SaaS-less approach, if a issue description is too messy/long, close it with "Please reopen with proper and concise description focusing on the issue" then lock it. Eventually people catch up and stop with the slop, just like in real life.

But you have to be able to say "No ...", rather than just slapping another subscription on top of an already broken workflow.


If you're maintaining OSS, that's understandable, and you're free to say no, but in the corporate world, that's not realistic, AI is here to stay, if they don't harness it they would just be left behind. even if the AI gets good and stops writing sloppy stuff, it's still gonna write a lot of stuff, and you're gonna review it anyway, and take responsibility and ownership, and it's still gonna take you more time, because the bottleneck is now reviewing and understanding the code.

I agree that the workflow is broken, but only on the reviewing side, AI is a tool we use to make products just like any other we used in the past, punch cards, machine code, assembly, ...etc. AI is just the new tool that sits on top of the code as the next level, no one codes with punch cards, no one writes machine code anymore, we used to write the compiled language and don't care about how it's compiled or turned into machine code, same with AI, although it's not there yet and still requires babysitting by engineers, but that's our new job now, and we need to learn how to use it and make our lifes easier.


> but in the corporate world

Sure, but that's irrelevant when someone says "I'm an OSS maintainer" and the context is explicitly about reviewing code submitted by others in a FOSS context, where you can say "No" and don't need any SaaS in order to do so.


That's not true at all of the corporate world. If your team is mass producing slop and you don't have processes in place to get it under control, you've got a big problem on your hand.

If any engineer sent me a 20,000 line refactor I'd immediately reject it and tell them to go back and start making changes incrementally at minimum. More likely I'd force them to have a whole design discussion with the team to make sure that what they are doing even makes sense.

What happens if they push out slop that significantly increases your infrastructure costs? What happens if they push out slop that significantly increases the number of bugs or outages? What happens if they push out slop that has no observational metrics, dashboards, or tooling?

In every case you push back on the team and make them fix their shit. I don't care if they are using LLMs or not. They are responsible for their work being sufficient quality. If they aren't meeting those standards, then they need to step it up.


I don't disagree with you on this, I worked my whole life in corporate and haven't worked as a OSS maintainer before, though I will _and already did_ reject PRs way less than that, I speak for myself and my team here and it's unrealistic to ship a single PR as complex as this, we usually plan features as tech designs with PRs of no more than 500 LOC, but that doesn't mean we could never have a 20k PR at all. in my experience, those huge PRs are usually the simple ones where most of it is just noise. I did one recently and moved the UI library in one of our old codebases three major versions up to the very latest, although it was 20k lines of changes, all of it is just mechanical chanes, renames, codemod stuff, test fixes, snapshot updates, ...etc. and it's not realistc to split this into multiple smaller PRs as this can bring other complications like having multiple versions of the same UI library in the codebase, which could cause more problems than it fixes, AI helps with that kinda work a lot and I would've never been able to do this migration is such a short time without it. despite that, reviewing it was a UI challenge, not code, with UI libraries, the breaking changes are usually in the UI so you can't see it from the code, and we did have a special process to review it, although on the code side, Github was a nightmare to deal with reviewing this PR, we noticed that github was the bottleneck here since it lays out the code changes without much context and is already hard to navigate and stuggles with huge PRs, the review surface and the developer experince on github was horrible, and that's why I suggested you look for better alternatives, there are a lot out there and all of them are free for OSS so why not try them?

> Next up, at some point, ideally we get some v8-like runtimes where we can share libraries across multiple isolates!

I'm probably missing your point, but aren't wasm memories achieving exactly this? Just an example from wasmtime: https://docs.wasmtime.dev/examples-multimemory.html


> 2. Buy inexpensive, well-diversified mutual funds such as Vanguard Target 20xx funds.

I wouldn't recommend this after seeing how SpaceX was literally shoved down lots of people's throats.


> I wouldn't recommend this after seeing how SpaceX was literally shoved down lots of people's throats.

If you're going to buy a "total market" fund, then SpaceX is part of the market. There were strange financial things with GE, Enron, etc, and they were part of index(es): you have to take the good with the bad when it comes to human (economic) behaviour.

Most stocks suck:

* https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3710251

* https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2900447

* https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4541122

but you don't know ahead of time which will go from not-sucking to sucking (LSE: RR is up 10x in the last five years), or vice versa. Predicting the future is hard:

* https://en.wikipedia.org/wiki/A_Random_Walk_Down_Wall_Street

so it's not worth the effort for the vast majority of people.


To me, investing is NOT just getting the best outcome possible. I simply don't agree with some companies practices and therefore I don't want to invest in them. I believe I am better off if I live in a better society overall than if I have more money in a worse overall society.


> I simply don't agree with some companies practices and therefore I don't want to invest in them.

Understandable, but unless you buy the stock from them at IPO, you're not giving them money. I agree with Cullen Roche's four points on ESG investing; second one:

> 2) The secondary market is a bad place to enact change. The intelligent defense of ESG is “by reducing the demand for a stock we can increase its cost of capital and impact its operating performance.” This is true to some degree, but I think this is dramatically overstated. For instance, the firms in the S&P 500 are all large established firms that have more than enough capital to finance their operations. They aren’t using the secondary equity markets to fund their operations. In fact, most firms have so much capital that they’ve been net buyers of stock in the last 50 years. So, this puts the cart before the horse. The better way to think of public companies is to think of them like horse betting. We can bet on the horses, but secondary market purchases are just private exchanges, not cash issuance to firms. As a result, betting on the horses doesn’t change the outcome of the race. Similarly, our secondary market purchases and sales have a far smaller impact on the firm’s operations than we might think.¹

* https://www.pragcap.com/my-view-on-esg-investing/

Roche's point in 'doing good' with investing is to make as much money as you can and then fund the movements and organizations that you wish to succeed (worked for the Koch brothers and others of their ilk).


PGlite - Postgres in wasm

Loads of useful things in the pipeline: multi connection support, native library, extensions and many more ideas.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: